Vulnerability Description
Sophos Cyberoam UTM CR25iNG 10.6.3 MR-5 allows remote authenticated users to bypass intended access restrictions via direct object reference, as demonstrated by a request for Licenseinformation.jsp. This is fixed in 10.6.5.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sophos | Cyberoam Cr25Ing Utm | - |
| Sophos | Cyberoam Cr25Ing Utm Firmware | 10.6.2 |
Related Weaknesses (CWE)
References
- https://infosecninja.blogspot.in/2017/04/cve-2016-7786-sophos-cyberoam-utm.htmlTechnical DescriptionThird Party Advisory
- https://www.exploit-db.com/exploits/44469/
- https://infosecninja.blogspot.in/2017/04/cve-2016-7786-sophos-cyberoam-utm.htmlTechnical DescriptionThird Party Advisory
- https://www.exploit-db.com/exploits/44469/
FAQ
What is CVE-2016-7786?
CVE-2016-7786 is a vulnerability with a CVSS score of 8.8 (HIGH). Sophos Cyberoam UTM CR25iNG 10.6.3 MR-5 allows remote authenticated users to bypass intended access restrictions via direct object reference, as demonstrated by a request for Licenseinformation.jsp. T...
How severe is CVE-2016-7786?
CVE-2016-7786 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-7786?
Check the references section above for vendor advisories and patch information. Affected products include: Sophos Cyberoam Cr25Ing Utm, Sophos Cyberoam Cr25Ing Utm Firmware.